Re: [RFC 1/1] security-process: update process information

2020-11-25 Thread Darren Kenny
On Wednesday, 2020-11-25 at 18:18:56 +0530, P J P wrote: > Hello Darren, all > > +-- On Tue, 24 Nov 2020, Darren Kenny wrote --+ > | I always understood triage to be the initial steps in assessing a bug: > | > | - determining if it is a security bug, in this case > | - then deciding on the

Re: [RFC 1/1] security-process: update process information

2020-11-25 Thread P J P
Hello Darren, all +-- On Tue, 24 Nov 2020, Darren Kenny wrote --+ | I always understood triage to be the initial steps in assessing a bug: | | - determining if it is a security bug, in this case | - then deciding on the severity of it | | I would not expect triage to include seeing it through

Re: [RFC 1/1] security-process: update process information

2020-11-24 Thread Red Hat Product Security
Hello! INC1531976 ([RFC 1/1] security-process: update process information) has been updated. Opened for: Prasad Pandit Followers: stefa...@gmail.com, peter.mayd...@linaro.org, sstabell...@kernel.org, Petr Matousek, p...@fedoraproject.org, konrad.w...@oracle.com, michael.r...@amd.com, m

Re: [RFC 1/1] security-process: update process information

2020-11-24 Thread Darren Kenny
Hi Prasad, Thanks for writing this up. I have some comments below on the response steps. On Tuesday, 2020-11-24 at 19:52:38 +0530, P J P wrote: > From: Prasad J Pandit > > We are about to introduce a qemu-security mailing list to report > and triage QEMU security issues. > > Update the QEMU

[RFC 1/1] security-process: update process information

2020-11-24 Thread P J P
From: Prasad J Pandit We are about to introduce a qemu-security mailing list to report and triage QEMU security issues. Update the QEMU security process web page with new mailing list and triage details. Signed-off-by: Prasad J Pandit --- contribute/security-process.md | 105